Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Implementing "frictionless sharing" with POST doesn't look trivial to me, because browsers treat cross-domain POST requests more strictly than GET.


The javascript would just have to create a form and submit it. Not a big problem at all. Alternatively, create an iframe in which the form is autosubmitted via javascript.


Doesn't that break the back button, making it no longer "frictionless"?


What makes you think that? CSRF vulnerabilities are possible precisely because cross-domain POST requests can be created without violating the cross-domain policy.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: